Wednesday, December 8, 2021

IR A-Z

Earlier this year I updated my paper entitled, "IR A-Z" for a talk that I was giving at the Magnet Forensics Summit, so I wanted to put its new link here. Enjoy! https://bit.ly/31JHGoF

Thursday, November 18, 2021

Book Review

What was your high school experience like? For me, high school was a struggle. Not because of the material, I was a top student...but the spring of my junior year, it was period two, and I was sitting in my English Literature class when there was a knock on the door. It was my brother and his wife, and I knew why they were there. My father was in the hospital, and had been in a coma for ten days.  Losing my dad tore me apart, and the next several years were the most difficult of my life.

High school counselors can play a critical, and pivotal, role in a student’s life, and we know that our youth are the future, so we need to invest heavily in them.  If you know someone in the education sector, do them a favor and get them a copy of this book. It’s a great stocking-stuffer by a fantastic counselor who just happens to be my mother-in-law, Nancy Regas. 

https://smile.amazon.com/Art-Being-School-Counselor-Authenticity/dp/1977235964

Sunday, May 2, 2021

InfoSec101 CheatSheet

So, you’re new to InfoSec you say?  How can I help?  Below are a few resources that I just put together for one of my mentee’s.  I offer a bunch of InfoSec links over at my DFIRLinks site: https://dfirlinks.blogspot.com.  The formatting on the blog is a bit wonky, so if you want this cheatsheet as a PDF, go here:  https://bit.ly/InfoSec101.

Jason Blanchard:
-Jason is amazing.  He runs a twice-weekly job search meet-up.  Jason works for one of the leading Cyber Security firms called Black Hills InfoSec (BHIS), owned by an industry luminary, John Strand. 

Schedule: 
Tuesday Nights: 7-9pm ET 
Friday Afternoons: 1-3pm ET 

-Jason's job meet-up group meets over Twitch, once or twice each week.  It covers job hunting tactics and techniques, resume and interview tips, and much more.  People looking to fill open positions sometimes attend, and even recruiters have been known to attend because it’s so popular with strong candidates: https://www.twitch.tv/banjocrashland.

-Jason has archived some of the meet-ups on the BHIS YouTube channel: https://www.youtube.com/c/BlackHillsInformationSecurity/videos, and they are also on his Twitch channel: https://www.twitch.tv/banjocrashland/videos

-Jason's online handle is @BanjoCrashLand: 
"We're doing a 5-part extended series on each one of the aspects of the job hunt. 
52+ viewers have landed new jobs so far since March 2020."
 
Black Hills InfoSec (BHIS): 
BHIS runs weekly Cyber Security WebCasts which they often record and post afterward.  I try to never miss them!  They also offer discounted (pay what you can) training: 

Be sure to follow them on Twitter: https://twitter.com/BHinfoSecurity.

They also have an active Discord server: https://discord.gg/4mJ7Hf7W.

-Here’s an example of their “Pay what you can” training: 

Wild West Hackin’ Fest: 
Wild West Hackin’ Fest is a Cyber Security conference by the folks at BHIS: 

-Here's an example WebCast from BHIS: The Dirty Truth Behind Breaking into Cybersecurity: 

Be sure to follow them on Twitter: https://twitter.com/WWHackinFest
They also have an active Discord server: https://discord.gg/wwhf.

Active Counter Measures (ACM):
John Strand of BHIS also runs: Active Counter Measures: https://www.activecountermeasures.com
 
-ACM often runs free Threat Hunting classes: https://www.activecountermeasures.com/events

Be sure to follow them on Twitter: https://twitter.com/ActiveCmeasures

They also have an active Discord server: https://discord.com/invite/2JjfB7E

Dave Kennedy/TrustedSec/Binary Defense: 
Dave Kennedy runs two companies (Trusted Sec and Binary Defense), and he has been known to “tweet” when they are hiring (often Junior level): 
"My favorite thing this year is we are opening up our junior program. To get new folks to INFOSEC trained up and into the field. Where best to learn!? #TrustedSec We are crazy hiring over at #TrustedSec and #BinaryDefense with more jobs being posted in the next few days. Have to shape our future, and more than pumped to have new folks coming into the industry." 

Be sure to follow them on Twitter: https://twitter.com/HackingDave

They also have an active Discord server: https://discord.gg/trustedsec

SANS Institute: 
Great courses as well as many free offerings: https://www.sans.org/free

Check out their “New-to-Cyber Field Manal”: 

Train up!  CTF’s: 
I offer a bunch of links to CTF’s and training video’s: https://dfirlinks.blogspot.com, below is a sample: 
(1) Watch Ed's CTF talk which begins about 17.5 mins in: 
(5) Smash the Stack: http://smashthestack.org 
(6) picoCTF: https://picoctf.com 
(7) WarGames (Bandit is recommended): https://overthewire.org/wargames 
(8) Daily CTF, just one challenge per day: https://nw3.ctfd.io/challenges 
(17) Hack the Box (free account works fine): https://www.hackthebox.eu 
(19) Cyber Defenders: https://cyberdefenders.org/labs 
(20) Try Hack Me: https://tryhackme.com

I can count on one hand the recruiters whom I respect, and that’s as nice as I can put it; sorry, not sorry - been burned one too many times.  That being said, I do have two fantastic recruiters whom I can highly recommend:

Katie Owston 
Email: katie.owston@glocomms.com 

John Terkovich 
Email: John@TerkoTech.com